Database/Kernel, userspace & hypervisor
Linux kernel mlx5_core IPsec full offload (ESN handling): The extended-sequence-number wrap event can be processed
Impact
The extended-sequence-number wrap event can be processed twice because the arm flag is re-set too late while the xfrm state lock is dropped and retaken. The driver then programs invalid ESN state, anti-replay fails, and all IPsec traffic on that SA halts. Operationally this is a stall of encrypted east-west traffic, not a memory-safety bug - but on an encrypted fabric it looks like a hard partition.
Who can reach it
Remote and unauthenticated in effect: an IPsec peer driving enough traffic to wrap the sequence number reaches the race. No credentials on the host.
What to do
Upgrade the host kernel to 7.0 or a stable backport (6.6.130, 6.12.78, 6.18.20, 6.19.10). Rolling reboot of IPsec-offload nodes. Interim: shorten SA rekey intervals so ESN wrap is not reached, a config change on the IKE daemon.
References
Related entries
- Linux kernel (net/xfrm): One crafted inner IPv4 header (tot_len = 0) inside an IPTFS payload puts the receive path intoCVE-2026-31472 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): A peer that mixes zero-copy-eligible and copy-path IPTFS fragments in one datagram makesCVE-2026-31517 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock withCVE-2026-43253 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/intel): The 128-bit VT-d context entry is zeroed with multiple writes while its Present bitCVE-2026-45944 · Linux kernel (drivers/iommu/intel)High
- Linux kernel SMC (early link-group access on CLC decline in smc_clc_wait_msg): A peer can send a CLC decline before theCVE-2026-46027 · Linux kernel SMC (early link-group access on CLC decline in smc_clc_wait_msg)High
- Netty: client TLS silently skips hostname verification when a plain X509TrustManager is suppliedCVE-2026-50010 · Netty (SimpleTrustManagerFactory / X509TrustManagerWrapper hostname verification)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.